Watchmaker
0.23.2
  • Installation
  • Configuration
  • Usage
  • Common Scan Findings
    • Common Scan Findings for EL7
      • Findings Summary-Table
      • Use Only FIPS 140-2 Validated Ciphers
      • Use Only FIPS 140-2 Validated MACs
      • Modify the System Login Banner
      • Enable Smart Card Login
      • Configure the Firewalld Ports
      • Set Default firewalld Zone for Incoming Packets
      • Disable Kernel Parameter for IP Forwarding
      • The Installed Operating System Is Vendor Supported
      • Install McAfee Virus Scanning Software
      • Enable FIPS Mode in GRUB2
      • Configure AIDE to Use FIPS 140-2 for Validating Hashes
      • Verify and Correct Ownership with RPM
      • Verify and Correct File Permissions with RPM
      • Ensure Users Re-Authenticate for Privilege Escalation - sudo NOPASSWD
      • Operating system must display the date and time of the last successful account logon upon logon
  • Frequently Asked Questions
  • API Reference
  • Contributing
  • Changelog
Watchmaker
  • »
  • Common Scan Findings
  • Edit on GitHub

Powered by Plus3 IT Systems

Common Scan Findings¶

There is frequently more than one way to achieve a given hardening-recommendation. As such, generic security scanners may produce alerts/findings that are at odds with the actual system state implemented by Watchmaker. The following are frequently-cited findings and explanations for why a scanner may alert on the Watchmaker-managed configuration-state.

Common Scan Findings for EL7¶

  • Findings Summary-Table
  • Use Only FIPS 140-2 Validated Ciphers
  • Use Only FIPS 140-2 Validated MACs
  • Modify the System Login Banner
  • Enable Smart Card Login
  • Configure the Firewalld Ports
  • Set Default firewalld Zone for Incoming Packets
  • Disable Kernel Parameter for IP Forwarding
  • The Installed Operating System Is Vendor Supported
  • Install McAfee Virus Scanning Software
  • Enable FIPS Mode in GRUB2
  • Configure AIDE to Use FIPS 140-2 for Validating Hashes
  • Verify and Correct Ownership with RPM
  • Verify and Correct File Permissions with RPM
  • Ensure Users Re-Authenticate for Privilege Escalation - sudo NOPASSWD
  • Operating system must display the date and time of the last successful account logon upon logon
Next Previous

© Copyright 2016, Plus3 IT Systems. Revision 2baf0773.

Built with Sphinx using a theme provided by Read the Docs.
Read the Docs v: 0.23.2
Versions
latest
stable
0.23.2
0.23.1
0.23.0
0.22.2
0.22.1
0.22.0
0.21.9
0.21.8
0.21.7
0.21.6
0.21.5
0.21.4
0.21.3
0.21.2
0.21.1
0.21.0
0.20.5
0.20.4
0.20.3
0.20.2
0.20.1
0.20.0
0.19.0
0.18.2
0.18.1
0.18.0
Downloads
On Read the Docs
Project Home
Builds